HTTP: Phorum Read Access

This signature detects access to the vulnerable read.php3 script installed with Phorum. Because the script does not validate input, attackers can execute arbitrary SQL statements to modify the database contents, insert new entries, create and drop tables, etc.

Extended Description

By sending a specially-crafted URL request, an attacker could execute arbitrary SQL commands on the server.

Short Name
HTTP:PHP:PHORUM:READ-ACCESS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Access CVE-2000-1233 Phorum Read
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown
CVSS Score

7.5

Found a potential security threat?